mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
21 lines
1.2 KiB
Markdown
21 lines
1.2 KiB
Markdown
### [CVE-2024-29974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29974)
|
||

|
||

|
||
C0%20&color=brighgreen)
|
||
C0%20&color=brighgreen)
|
||

|
||
|
||
### Description
|
||
|
||
** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED **The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
|
||
- https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
|
||
|
||
#### Github
|
||
No PoCs found on GitHub currently.
|
||
|